Cyber Readiness Workshops

Grow beyond the technical and tactical with our two in-person workshops: CIRP Development and our Advanced Program.

CIRP Development Workshop

Pre-Workshop

  • Two months of weekly calls with a member of my team filling out “worksheets” that will help us pre-build your CIRP/TTX slides prior to your arrival.

Day 1

  • InfoSec & CIRP 101
  • Section 3: “Incident Preparation.”
  • Section 5: “Incident Response.”
    • Requirements Driven Execution: Building a Roles & Responsibilities table with each contact for each of your Use Cases.

Day 2

  • Section 2: “Introduction & Purpose.”
  • Section 4: “Incident Detection, Analysis, and Declaration.”
  • Section 6: “Post-Incident Activity.”

Day 3

  • Review of the CIRP Executive Management Overview (Section 3.1).
  • Ensure the CIRP aligns with your Cyber Risk Narrative, leveraging a Cyber Risk x CIRP Matrix.
  • TTX 101

Review next steps for you once you get back:

  • Socialization of the CIRP
  • Conduct the Cyber Insurance call.
  • Conduct the “Walk Through”/“TTX”.
  • Start your Lessons Learned program.
  • Conduct routine maintenance of the CIRP.
  • Develop your technical process guides.
    • I will be referring you here to some very qualified people who can help.

Workshop Deliverables

  • Customized Draft CIRP.
  • TTX Slides, “Speaker Notes”, and sample email invite.
  • Cyber Insurance Questionnaire and sample email invite.
  • Customized Cyber Risk x CIRP Matrix to demonstrate that your CIRP is aligned with your cyber risks.
  • Analysis of your most recent Annual Report (for public companies).
  • A certificate for 18 CPE hours.
  • A signed copy of my McGraw-Hill CIRP book.
A more detailed project plan and sample Table of Contents are available upon request.

Our Advanced Program is for those CISOs who are ready to grow beyond the “Technical” and “Tactical” realm and become “Board-Ready.”

We’ve partnered with Colin Anderson to co-present our “Advanced Program” workshops. Colin is an 18-year CISO (Safeway, Levi Strauss, & Dayforce) and winner of the (Global) CISO100 award for the last five years, and a friend since our days at Pacific Bell Network Integration (PBNI) back in the late ‘90s.

Pre-Workshop

Two months of weekly calls with worksheets that will help pre-build your documentation prior to your arrival:

  • Cyber Risk Narrative review & development
  • InfoSec policy review & development
  • Corporate Crisis Management Plan / COOP review
  • Crisis Communications SOP review
  • SIEM Correlation logic (aka “context”) build out

Day 1: Top Down

Neal: The New ERA of BOD Cyber Risk Oversight

  • The recent SEC guidance raising the bar for BODs.
  • Leveraging industry frameworks (e.g., PCI, NIST, ENISA, ISO 27K, etc.) when presenting to your BOD.
  • “Policy – Plan – Procedure.
  • Development of your InfoSec Policy
  • Development of your IR Policy
  • The CIRP Executive Management Overview.*

Colin: Working with the Board

  • Know your Board
  • What matters to the Board
  • What does the Board expect from you
  • Coaching your Board

Day 2: “Risk Based”

Neal: Your BOD understands risk. Make sure your IR/InfoSec is Risk-Based.

  • Enterprise Risk Management (ERM) 101
  • Risk-Based IR & InfoSec Approach
  • Leveraging “Context” of your highest risks to develop specific controls

The Benefits

  • Validation of your Controls Frameworks, Policy Objectives, and overall Organizational Information Security objectives
  • Context is essential in developing Detective controls such as SIEM correlation logic and event Runbooks (true story)
  • During an actual Cyber Intrusion Incident, it is critical the organization has an idea of what “normal” looks like so they can quickly identify “abnormal.”
  • Privileged Access Management – Just the manual version (true story)
  • Segregation of Duty/Single Point of Failure Analysis (true story)
  • Validating/Improving your Logging Strategy
  • Developing/Improving your Containment Plan
  • Identify High-Risk Users, Service Accounts, etc.
  • “90% of your Cyber Risk lies in 5% of Users” (true story)

Colin: Operational Excellence

  • Financial management
  • Building & developing the security team
  • Security operations & incident response
  • Metrics that matter

Day 3: Business Due Diligence

Neal: Helping you work with the rest of the management team

  • Ensure a “Business-Focused” approach
  • Requirements Driven Execution*
  • Cyber Insurance 101*
  • Crisis Management 101
  • CIRP Incident Coordinator Quick Guide Review*

Colin: Business Aligned Security Strategy

  • Business objectives & threat landscape
  • Building a risk-based security strategy
  • Compliance & governance in strategy
  • Cybersecurity’s value to the business

Workshop Deliverables

  • Customized Cyber Risk Narrative Example*
  • Customized Draft InfoSec Policy
  • Board Ready Presentations
  • Sample 7×24 Turnover/Management briefing slides
  • ERM Cyber Risk Portfolio Example.
  • Sample Cyber Risk x InfoSec Framework Matrix for your highest value cyber risk item to demonstrate that your program is aligned with your cyber risks
  • “Context” worksheet for your highest value cyber risk items
  • Starter SIEM Correlation logic for your highest value cyber risk item
  • A certificate for 18 CPE hours
  • A signed copy of my McGraw-Hill CIRP book*

Items with an asterisk (*) are also provided in the CIRP workshop.

Full Disclosure: Colin is still functioning as a full-time CISO. His participation in each workshop may differ based on its location and his availability. His presentations may be pre-recorded and should last approximately two hours. Colin will then be available either by Microsoft Teams call or onsite to answer any questions for the third hour.

Payment

The workshops cost $10,000 each and you are responsible for your travel, lodging, and meals not provided during the three days.

The $10,000 is due upon registration. Each venue is different, but typically:
  • If you or I cancel prior to the venue non-cancellation period (I will tell you when that is), you will get 100% back.
  • If you cancel greater than 4 weeks prior to the event, I will refund you $7,500.
  • If you cancel within four weeks of the event or are a “no-show,” I will provide you with all the “Pre-Workshop” materials we’ve developed for you up to that point, but your deposit is non-refundable.
  • Your participation may be rescheduled if there is space available in a subsequent workshop.
  • While in-person participation is preferred, and on-site attendees will be given priority, if you are unable to be on-site and are unable to reschedule, you can participate via Teams. Every effort will be made to provide you with the workshop deliverables. Teams can be unreliable, and the quality of your experience and deliverables may be affected. We will not “loop back” to cover team outages. You can also designate another person to take your place either on-site or online.
  • If I cancel for any reason, at any time, you will get a full refund.
If you are a paid participant in either of the workshops, and another principal (e.g., BOD member, GC, CRO, YOUR backup, etc.) from your organization wants to work on this with you, if there is space available, they can attend/ call in for free. (All I ask is that they be an active participant and share their perspectives with the collective.) Each participant will be identified by first name, title, and industry in the hope of fostering candid conversations.

2026 Schedule

Date Workshop Location
February 17–19 CIRP Workshop San Diego (Coronado), CA
March 31–April 2 The Advanced Program Workshop San Diego (Coronado), CA
April 21–23 CIRP Workshop New York City
April 28–30 The Advanced Program Workshop New York City
May 12–14 CIRP Workshop Paris, France
May 19–21 The Advanced Program Workshop Paris, France
July 14–16 CIRP Workshop San Diego (Coronado), CA
July 21–23 The Advanced Program Workshop San Diego (Coronado), CA
September 15–17 CIRP Workshop London, England
September 22–24 The Advanced Program Workshop London, England
October 6–8 CIRP Workshop New York City
October 13–15 The Advanced Program Workshop New York City
November 3–5 CIRP Workshop Omaha, Nebraska
November 10–12 The Advanced Program Workshop Omaha, Nebraska
December 1–3 CIRP Workshop Waikiki, Hawaii
December 8–11 The Advanced Program Workshop Waikiki, Hawaii

These dates are subject to change or cancellation.

Let's get started.

You must grow beyond a technical and tactical perspective in today’s cyber security landscape.